3 ms·
Hi HN! I made Blogsend.io. It's a way for blog owners to handle emailing their readers automatically whenever they make a post. I built this because I actually
by fiiv 8y ago
Hi HN! I made Blogsend.io.
It's a way for blog owners to handle emailing their readers automatically whenever they make a post. I built this because I actually needed it first, but decided to try it out as a product as well.
Technically it's not terribly complicated – it has a widget which collects emails of your subscribers and it listens to your RSS feed and emails those people when you post. The goal is to make it as hands-off and hassle-free as possible to email out your content to your readers.
Built it in Node.js and Postgres, with Bulma providing the CSS defaults. I vowed to move fast in this project and to that end I decided to stay away from frontend frameworks and build the old fashioned way, with <form> tags! It was actually super fun. I've had my hands on React, Vue, Angular and Ember before, and in all of them I actually never really felt as if it felt as natural as this approach.
Anyways, I'd love to hear any feedback you might have :)
- catchmeifyoucan 8y agoDo you store the list of emails per blog?
- fiiv 8y agoYes, I do! At present they're not exportable though. I think one part of the product that's nice in that way is that as a subscriber, you know you don't need to think about your email getting spammed - communicating with subscribers is only done as a post is published.
- vincentmarle 8y ago> At present they're not exportable though. You may want to think this one more through. As a publisher, I would definitely be in the market for your product but the mailing list is the most valuable (and expensive) data set I will be working on for years, and to have it not exportable in the case that you might go out of business or if I decide to use another product is a definite showstopper for me.
- fiiv 8y agoThat makes sense! Just out of curiosity, what size is your blog? I spoke to several blog owners of various sizes. The smaller ones tended to not care about this, but indeed the bigger ones took more of an interest in the actual emails they collect. Just wondering if you'd fall into one of these categories.
- jamieweb 8y agoThis looks really good, and I've been interested in setting up a system like this for my blog for a while. My main concern with anything these days is security. Do you have any further info on how you secure the email list that you store, etc?
- fiiv 8y agoA sensible question. Firstly, from a philosophical perspective I am at no point exposing emails of subscribers to the blog owners. The communications they send to those subscribers are limited to what's published in the RSS feed (once per new post). As for in terms of infrastructure and app design, I contemplated the idea of implementing some kind of encryption or email alias system for a while, but ultimately decided against it. Some basic reasons are the ones also shared in the answers to this question on Stackoverflow: https://stackoverflow.com/questions/767276/what-is-the-best-and-safest-way-to-store-user-email-addresses-in-the-database https://stackoverflow.com/questions/767276/what-is-the-best-... Since there is no direct access to emails via the logged in user's interface nor is there any kind of public or semi-public database access (through for example an API – the app is entirely server-side rendered), I already limit the damage that can be done through spoofed or stolen credentials (everything from a stolen password to a spoofed or stolen auth cookie). The database does store emails of course, but the db is isolated from the application on a different server. At launch I used a Heroku hosted database but I'm planning to provision a database environment that is only open to private network IP access. I'm also definitely interested in beefing it up further. Any advice?
- jamieweb 8y agoThanks for the info - it sounds like you've got things locked down pretty well already. The key bit as you say is the fact that the emails are stored on a system that is not publicly accessible. My biggest worry with anything like this is that if there is a breach at Blogsend that affects the readers of my blog, I'm still responsible for it as I'm the one who put the form on my site and encouraged my readers to enter their email address. The last thing I want to have to do is use Blogsend to send a "Notice of data breach" email! :) I've run my own similar system before (just for my blog) where readers could enter their email address, verify it and then receive notifications when I post. However, I discontinued this system as I didn't want the burden of storing personal data like that. One think you could check out is adding security HTTP response headers - your site is pretty clean and simple so it should be relatively easy to get it locked down tightly. See https://securityheaders.com/ https://securityheaders.com/.
- GoRudy 8y agoHow do you envision this working for sites that publish more then once per day, say even 5 - 10 posts per / day?
- fiiv 8y agoGood question! On my roadmap is a feature where you can have more control over what's sent. So for example whitelist or blacklist categories, set specific send times and for example doing a mailing once a week or day or month (user specified time frame) where the posts of that time period end up in a recap/newsletter/aggregate email.